CVE Vulnerabilities

CVE-2007-4352

Published: Nov 08, 2007 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.6 HIGH
AV:N/AC:H/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Array index error in the DCTStream::readProgressiveDataUnit method in xpdf/Stream.cc in Xpdf 3.02pl1, as used in poppler, teTeX, KDE, KOffice, CUPS, and other products, allows remote attackers to trigger memory corruption and execute arbitrary code via a crafted PDF file.

Affected Software

NameVendorStart VersionEnd Version
XpdfXpdf3.0.1_pl1 (including)3.0.1_pl1 (including)
Red Hat Enterprise Linux 3RedHatxpdf-1:2.02-11.el3*
Red Hat Enterprise Linux 4RedHatcups-1:1.1.22-0.rc1.9.20.2.el4_5.2*
Red Hat Enterprise Linux 4RedHatkdegraphics-7:3.3.1-6.el4_5*
Red Hat Enterprise Linux 4RedHatgpdf-0:2.8.2-7.7.1*
Red Hat Enterprise Linux 4RedHattetex-0:2.0.2-22.0.1.EL4.10*
Red Hat Enterprise Linux 4RedHatxpdf-1:3.00-14.el4*
Red Hat Enterprise Linux 5RedHatcups-1:1.2.4-11.14.el5_1.3*
Red Hat Enterprise Linux 5RedHatpoppler-0:0.5.4-4.3.el5_1*
Red Hat Enterprise Linux 5RedHattetex-0:3.0-33.2.el5_1.2*
GpdfUbuntudapper*
GpdfUbuntuedgy*
KofficeUbuntudapper*
KofficeUbuntudevel*
KofficeUbuntuedgy*
KofficeUbuntufeisty*
KofficeUbuntugutsy*
KofficeUbuntuhardy*
KofficeUbuntuintrepid*
KofficeUbuntujaunty*
KofficeUbuntukarmic*
KofficeUbuntuupstream*
LibextractorUbuntudapper*
LibextractorUbuntudevel*
LibextractorUbuntuedgy*
LibextractorUbuntufeisty*
LibextractorUbuntugutsy*
LibextractorUbuntuhardy*
LibextractorUbuntuintrepid*
LibextractorUbuntujaunty*
LibextractorUbuntukarmic*
Pdfkit.frameworkUbuntudapper*
Pdfkit.frameworkUbuntuedgy*
Pdfkit.frameworkUbuntufeisty*
PdftohtmlUbuntudapper*
PdftohtmlUbuntuedgy*
PdftohtmlUbuntufeisty*
PopplerUbuntudapper*
PopplerUbuntudevel*
PopplerUbuntuedgy*
PopplerUbuntufeisty*
PopplerUbuntugutsy*
PopplerUbuntuhardy*
PopplerUbuntuintrepid*
PopplerUbuntujaunty*
PopplerUbuntukarmic*
PopplerUbuntuupstream*
XpdfUbuntudapper*
XpdfUbuntuedgy*
XpdfUbuntufeisty*
XpdfUbuntugutsy*
XpdfUbuntuupstream*

References